#Andardoor

Malware/Tool

2023-02-15 • 취약한 Innorix 악용한 악성코드 유포

Andardoor is a Windows backdoor observed in attacks that exploited a vulnerable Innorix Agent file-transfer client. C/C++ and .NET samples had the same capabilities: collecting and sending host information, capturing the screen, and creating and executing files. The malware connects to command-and-control servers and encrypts transmitted data through an encoding and decoding routine to hinder packet monitoring. Its XOR key matches a value documented in a 2017 CISA report. Some samples established persistence through a scheduled task whose name referenced AhnLab.

Tagged Reports

« Back